Discrezo Trust Center
Trust should be inspectable.
Discrezo is built around a simple idea: no single party should need both your identity and your AI conversation. This Trust Center explains the architecture, controls and independent assurance behind that claim.
See what we know. What AI providers receive. What is encrypted. What has been independently certified. And where work is still in progress.
ISO/IEC 27001 certified
You
Who you are
Account
- Account
- Subscription
- Billing
What you ask
AI inference
- Prompt
- Context
- Response
Encrypted history
Ciphertext only on Discrezo servers.
Nobody needs the whole picture.
At a glance
What you should know before you trust us.
ISO/IEC 27001
Discrezo operates an ISO/IEC 27001-certified information security management system.
Account ↔ inference
The AI inference path does not need your Discrezo account identity to answer a request.
Saved history
Discrezo's backend does not hold the key required to read your saved conversation content.
Standard Mode
The AI provider receives the prompt and context needed to answer it without needing your Discrezo account identity attached.
Private Mode
Private Mode excludes OpenAI, Anthropic and Google from eligible prompt-processing routes.
Product security review
A product-specific independent security review is part of the launch programme and must not be described as complete until it is complete.
Privacy architecture
Different systems are allowed to know different things.
Discrezo does not rely on everyone inside one giant system promising not to look. The architecture gives different responsibilities to different parts of the service.
Account
Who
Can process
- Account
- Subscription
- Billing relationship
- Plan entitlement
Does not need
- Readable AI conversations
Inference
What
Can process
- Prompt
- Relevant context
- Selected route
- Generated response
Does not need
- Account email
- Payment identity
- Discrezo customer identity
Encrypted sync
History
Can hold
- Encrypted conversations
- Encrypted memory
Does not have
- The key required to read them
Each side gets what it needs. Nobody needs everything.
Important
Identity separation does not hide the words you type.
In Standard Mode, the AI provider processing your request can read the prompt and relevant context. If you type your name, employer, address or other identifying information into the prompt, the provider can read those words.
We separate your Discrezo identity from the request. We do not pretend the question itself is invisible.
Security
Security protects the privacy boundary.
The privacy model only works if the systems preserving it remain secure.
Credentials
Provider credentials stay server-side.
Credentials used to access AI providers are held within protected server-side systems and are not exposed to ordinary user browsers.
Access
Access follows responsibility.
Different systems and personnel should only receive the access required for their job.
Logging
A debugging system should not become a conversation archive.
Prompt and response bodies are designed to be excluded from ordinary inference logs.
Software
Privacy boundaries are treated as testable requirements.
Security checks include controls around secrets, dependencies and important privacy boundaries.
Incidents
Have the process before the problem.
Discrezo maintains incident-management processes for identifying, containing, investigating and responding to security events.
Independent assurance
Don't take every claim from us.
ISO/IEC 27001 certified.
Discrezo operates an independently certified information security management system under ISO/IEC 27001.
ISO 27001 provides a formal framework for identifying security risks, assigning controls, managing incidents, governing access and continually improving information security.
Certification validates the information-security management system within its certified scope. It does not mean every individual Discrezo product claim has automatically been independently penetration-tested.
Discrezo architecture review.
A separate product-specific independent security review is scheduled as part of the launch programme.
This review is intended to examine critical Discrezo-specific security and privacy boundaries.
It is not yet complete.
Certified where certified. In progress where in progress.
Future assurance
Further assurance will be listed here as it is completed. Areas we expect to cover include product security assessment, penetration testing, additional certifications, privacy architecture review, audit reports and transparency reporting. None of these are complete today, so none of them are listed as evidence.
AI providers
The model gets the question. It doesn't need your Discrezo account.
Standard Mode provider receives
- Prompt
- Relevant context
- Information necessary to generate the response
Standard Mode provider does not need
- Discrezo account ID
- Discrezo account email
- Payment identity
- Originating network identity
The words inside your prompt can still identify you if you put identifying information there.
A good model is not automatically an approved model.
Discrezo considers more than model quality when determining which routes are eligible. Privacy, security, availability and the user's selected mode also matter.
Quality
Is the model capable of answering the task?
Privacy
Does the route satisfy the privacy requirements of the selected mode?
Security
Is the provider configuration approved?
Availability
Is the route healthy enough to use?
Security constraints come before model preference.
Private Mode
When you exclude Big AI, the router cannot quietly put it back.
Private Mode restricts eligible prompt processing to supported open-model routes. Requests are not intentionally routed to OpenAI, Anthropic or Google.
Hard routing constraint
Provider eligibility is restricted before ordinary model selection.
No silent fallback
An excluded provider should not be used simply because it would otherwise provide a stronger answer.
Honest trade-off
Restricting model choice may affect performance on particularly difficult tasks.
Private means the privacy rule wins.
Your data
Stored does not mean readable.
Discrezo does not say “nothing is stored”. Saved conversation history may need to be stored so that it can sync between devices. The important question is what form that data takes and who can read it.
Your trusted device
Readable conversation
Encrypted before sync
Discrezo storage
Encrypted data
No backend decryption key
You can read your history. Discrezo cannot.
Discrezo may still observe limited information associated with storage and synchronisation, such as that encrypted data exists or that a sync occurred. Encryption does not make all metadata disappear.
Two types of keys
Service credentials
Used by Discrezo to access AI providers.
Protected server-side.
Conversation key
Used to read your saved conversation history.
Held by your trusted devices, not Discrezo's backend.
The key that lets us pay an AI provider belongs on our infrastructure. The key that lets someone read your history does not.
Observability
Know whether the system works without reading what you said.
Operational information
- Provider and route health
- Latency
- Token or compute volume
- Error category
- Service availability
Conversation content
Not intended for ordinary inference logs:
- Prompt body
- Response body
- Readable conversation history
- Account identity attached to inference logs
The safest unnecessary field is one that was never collected.
Software security
Security starts before deployment.
Threat modelling
We identify ways privacy boundaries could fail before relying on them.
Relevant threat categories may include
- Account-to-prompt correlation
- Metadata leakage
- Logging leakage
- Credential compromise
- Malicious routing inputs
- Client compromise
- Supply-chain risk
The internal threat model itself is not published.
Security checks
Software changes are checked for issues such as exposed secrets, vulnerable dependencies and violations of important privacy boundaries.
Human review
Automated checks support engineering review. They do not replace security judgement.
Router safety
A prompt can influence which eligible model is appropriate. It cannot give itself permission to override the user's privacy mode.
Operations
Security has to survive day-to-day operation.
Access control
Access is restricted according to role and need.
Security monitoring
Operational systems are monitored for failures and security events.
Incident response
Processes exist for containment, investigation and remediation.
Provider control
Problematic provider routes or credentials can be restricted where necessary.
Transparency
Tell people what is true. Especially when the answer is uncomfortable.
What we can read
Account information
Yes.
Discrezo needs account information to operate your subscription.
Saved conversation history
No readable copy.
There is no readable copy on Discrezo's backend where encrypted history is operating as designed.
Standard Mode prompt
Processed to answer it.
Processed by the inference path and the AI provider necessary to answer it.
Private Mode prompt
Eligible routes only.
Processed only through eligible Private Mode routes.
What we do not claim
We do not claim.
“Nothing is stored.”
Because encrypted history may be stored.
“AI providers cannot see your prompt.”
Because the AI answering a Standard Mode request needs to process it.
“Discrezo doesn’t know who you are.”
Because the account side needs to know who has an account and subscription.
“Private Mode means no external computer processes the prompt.”
Because infrastructure is still required to run eligible open models.
“Discrezo is unhackable.”
No responsible software company should say that.
“ISO 27001 proves every product claim.”
It does not.
Precise claims are stronger than bigger claims.
Legal requests
We can only provide what we have.
Like other companies, Discrezo is subject to valid legal process. But there is an important difference between data stored by a system and information that system has the technical ability to read.
Account information
If lawfully required and available to Discrezo, this may be capable of disclosure.
Encrypted history
If Discrezo does not possess the key required to decrypt saved conversation data, receiving a legal demand does not create that key.
We do not claim that legal requests can never result in disclosure. We describe what the architecture actually allows us to access.
Transparency reporting.
PlannedAs Discrezo grows, we intend to publish appropriate information about legal requests and other matters relevant to user trust where doing so is lawful and meaningful.
Security research
Good security welcomes scrutiny.
Security concerns can currently be reported to support@discrezo.com while our dedicated vulnerability disclosure process is being established.
Documents
Read the details yourself.
Privacy Policy
How Discrezo handles Personal Information.
Security
Technical and organisational controls protecting Discrezo.
Terms of Use
Rules governing use of Discrezo.
Service Terms
Terms applying to specific Discrezo services and features.
Data Processing Addendum
Data-processing terms for Business customers.
Cookie Policy
How the Discrezo website uses cookies and similar technology.
Cookie choices
Review or change optional website tracking preferences.
Sub-processors
Sub-processor information is available to Business customers and a public list is being prepared.
In preparationCurrent status
Where we actually stand.
Area
Status
What it means
ISO/IEC 27001
Independent assurance over Discrezo's information-security management system within its certified scope.
Identity / inference separation
Built into the product design.
Encrypted conversation sync
Saved conversation data is designed to be encrypted before sync with no backend-held decryption key.
Privacy-boundary automated tests
Tests designed to protect critical architecture boundaries.
Provider privacy configuration verification
Routes must satisfy required provider configuration before launch.
Product-specific independent security review
Separate from ISO/IEC 27001 certification.
Public transparency reporting
Not published today. It will only appear here once it exists.
Vulnerability disclosure programme
Security reports can be sent to support@discrezo.com in the meantime.
Our principles
The standards we design around.
Separate
Do not put identity and readable AI activity together when the product does not require it.
Minimise
Do not give a system information it does not need.
Encrypt
Keep saved conversation content unreadable to infrastructure that only needs to store it.
Verify
Test important boundaries and seek external scrutiny rather than relying only on internal confidence.
What we are building
Better AI should not require giving one company the whole picture.
Automatic routing
Different tasks can be handled by different eligible models without requiring users to understand model selection.
Privacy-aware routing
The privacy mode constrains which models are eligible before normal model selection.
Encrypted memory
Personalisation should not require the backend to own a readable archive of someone's AI history.
Provider independence
Users should not need to build their entire AI life inside one model provider's account.
Our position
AI privacy should not be a specialist feature.
People increasingly use AI for work, relationships, ideas, finances, health questions and decisions they may never type into a public search engine. Privacy should therefore be part of the default architecture, not an expensive enterprise add-on.
That is why core Discrezo privacy protections are included across the Individual, Pro, Researcher and Business experience rather than reserved only for the highest-priced plan.
FAQ
Trust questions.
Saved conversation history is designed to be encrypted before sync, with Discrezo's backend not holding the key required to decrypt it. During a live request, the inference systems necessarily process the request so it can be routed and answered.
Trust, earned
Don't trust the slogan. Inspect the system.
Read the architecture. Check the limits. See what has been independently certified. Watch what changes.
Privacy is the architecture. Security keeps it true. Transparency lets you verify it.